Bug 609090
Summary: | Racoon daemon blocks on recv() call due to empty pfkey socket | ||
---|---|---|---|
Product: | Red Hat Enterprise Linux 5 | Reporter: | RHEL Program Management <pm-rhel> |
Component: | ipsec-tools | Assignee: | Tomas Mraz <tmraz> |
Status: | CLOSED ERRATA | QA Contact: | Ondrej Moriš <omoris> |
Severity: | urgent | Docs Contact: | |
Priority: | urgent | ||
Version: | 5.3 | CC: | ebenes, fnadge, jrieden, jwest, omoris, plyons, pm-eus, sgrubb, tao, tmraz, vincew |
Target Milestone: | rc | Keywords: | OtherQA, ZStream |
Target Release: | --- | ||
Hardware: | All | ||
OS: | Linux | ||
Whiteboard: | |||
Fixed In Version: | ipsec-tools-0.6.5-14.el5_5.4 | Doc Type: | Bug Fix |
Doc Text: |
When dumping the pfkey database the kernel used to return only part of the database due to the small socket buffer size. When racoon was deployed on a system with a large number of network security policy entries, the racoon coould not find all of the security policy entries in the database. The updated package supports a new configuration option pfkey_buffer to the racoon.conf file that allows to set the buffer size as appropriate for the deployment requirements.
|
Story Points: | --- |
Clone Of: | Environment: | ||
Last Closed: | 2010-08-24 06:59:15 UTC | Type: | --- |
Regression: | --- | Mount Type: | --- |
Documentation: | --- | CRM: | |
Verified Versions: | Category: | --- | |
oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
Cloudforms Team: | --- | Target Upstream Version: | |
Embargoed: | |||
Bug Depends On: | 590783 | ||
Bug Blocks: |
Description
RHEL Program Management
2010-06-29 12:00:30 UTC
Technical note added. If any revisions are required, please edit the "Technical Notes" field accordingly. All revisions will be proofread by the Engineering Content Services team. New Contents: When dumping the pfkey database the kernel used to return only part of the database due to the small socket buffer size. When racoon was deployed on a system with a large number of network security policy entries, the racoon coould not find all of the security policy entries in the database. The updated package supports a new configuration option pfkey_buffer to the racoon.conf file that allows to set the buffer size as appropriate for the deployment requirements. An advisory has been issued which should help the problem described in this bug report. This report is therefore being closed with a resolution of ERRATA. For more information on therefore solution and/or where to find the updated files, please follow the link below. You may reopen this bug report if the solution does not work for you. http://rhn.redhat.com/errata/RHBA-2010-0645.html |